Live in Minnesota · 80% EVV threshold in effect since July 1 · See what it means

Security and HIPAA

What protects your residents' data, stated plainly — including what we will not claim.

The short version

Every customer signs a Business Associate Agreement before any protected health information is loaded. Data is encrypted with AES-256 at rest and TLS 1.3 in transit. Multi-factor authentication is mandatory. Access is role-based, and PHI access generates audit log entries retained for seven years.

Infrastructure runs on AWS under a signed BAA, with databases in private subnets. SOC 2 Type II is in audit — not complete, and we will not describe it as complete.

Controls in place

Signed BAA, every customer

Executed before PHI is loaded, as part of onboarding rather than an afterthought. Ask and we send you the template to read first.

Encryption

AES-256 at rest, TLS 1.3 in transit, encrypted backups. No unencrypted copies of PHI at any layer.

Mandatory MFA

Required on all accounts. Not a toggle an administrator can disable for convenience.

Role-based access

Least-privilege by default. A DSP sees what a DSP needs; an administrator sees more; neither sees everything by accident.

Seven-year audit logging

Every PHI access logged with who, what and when. This is the record that answers a breach question, and the one a licensor asks about.

AWS with a signed BAA

Private RDS in isolated subnets, no public database path, infrastructure-level encryption and access controls.

Why this matters more for a small agency

Large organizations have a security officer. Most agencies running four homes do not, and the practical consequence is that security posture becomes whatever the software vendor decided by default.

That is why we make the defaults strict rather than configurable. MFA is not optional because an agency without a security officer should not have to know to turn it on. Access is least-privilege because the alternative is everyone being an administrator by the end of the first year.

A breach at a small provider is not a smaller version of a breach at a large one. It is frequently existential, and the reporting obligations are identical.

What we will not claim

We will not tell you that using our software makes you HIPAA compliant. It does not. HIPAA compliance is a program — your policies, your training, your practice — and software is one input to it.

We will not describe SOC 2 Type II as complete while it is in audit.

We will not guarantee an audit outcome. No vendor can, and the ones that do are telling you something about how they sell rather than how they build.

Read our BAA template →

Common questions

Will you sign a BAA?

Yes, before any PHI is loaded — not after, and not as a concession. It is part of onboarding. You can read our BAA template before you commit to anything: ask and we send it, no signature and no sales call required.

Where is data hosted?

AWS, under a signed Business Associate Agreement with AWS. Databases run in private subnets with no public network path.

How is data encrypted?

AES-256 at rest and TLS 1.3 in transit. Backups are encrypted with the same standard.

Is MFA required?

Yes, for all accounts. It is not an optional setting an administrator can switch off.

Do you have SOC 2?

SOC 2 Type II is in audit. We say that plainly rather than implying it is complete — if that distinction matters for your procurement, ask us for status and we will tell you where it stands.

Who at Sothcare can see our PHI?

Access is role-based and least-privilege. Staff access to customer data requires a documented reason, and every access generates an audit log entry retained for seven years.

What happens to our data if we leave?

You can export it. We do not hold your records hostage as a retention tactic — month-to-month terms would be meaningless if we did.

Procurement questions?

Email support@sothcare.com and ask for the BAA, security documentation or SOC 2 status. No form, no gate.

Book my 20-min demo